Skip to content
SiteList

qsa.sh — External security scan of your own IP, in your terminal

qsa.sh

Unclaimed listing

Is this your site?

Claim it

What it does

A terminal-based service that performs an external port and vulnerability scan of the user's own public IP address using open-source tools (naabu, nmap, nuclei), offering a free live-streaming tier and paid async/deep scan tiers.

Two ratings

SiteList review score

Delivers exceptional terminal-first utility and performance for security engineers. Mid-funnel content gaps and technical configuration errors limit its reach.

Reviewed on Aug 3, 2026

Why this score? →

Screenshots

Captured during our latest review on Aug 24, 2026

Home · qsa.sh
Pricing · qsa.sh
About · qsa.sh
How it works · qsa.sh

Pricing details

Free tier available; Full plan is $5/mo via PayPal; Deep scan is a $7 one-time purchase per scan. Billed monthly.

PlanPriceDetails
Free$0 monthly per scan

Live terminal stream, ~30 seconds. Top 1,000 ports, ~2,000 nuclei checks. 1 scan per IP per 24h · Top 1,000 TCP ports only · Open ports, versions & top 3 findings only · Nothing stored

View source
Full$5 monthly per subscription

Async delivery. All 65,535 ports + ~2,000 high-signal nuclei checks. 1 scan per hour · Full list + remediation guidance · Single-read or 24h Redis retention

View source
Deep$7 one time per scan

Async emailed report. All 65,535 ports + full nuclei template set. Unlimited scans · Full list + remediation, emailed · Single-read or 24h Redis retention

View source
View source

Key features

  • External port scanning

    Security scanning

    Probes open TCP ports on the user's public IP using naabu and nmap.

  • Vulnerability detection

    Security scanning

    Maps service banners to known CVEs using nmap vulners script and nuclei templates.

  • Live terminal streaming

    Delivery method

    Streams scan results directly to the user's terminal in real-time.

  • Zero data retention

    Privacy & security

    Scan results are ephemeral, streamed only, and never written to disk or stored long-term.

  • IP opt-out mechanism

    Privacy & security

    Allows users to permanently exclude their IP or CIDR range from being scanned via a contact form.

View source

Who it’s for

  • Self-audit of public infrastructure

    Verifies what external attackers can see of a host's open ports and vulnerabilities.

  • Terminal-based quick security check

    Provides a fast, install-free way for developers to run a surface-level scan directly from the command line.

View source

Buyer questions

Questions buyers actually ask

Is qsa.sh suitable for professional security audits?

Yes. The tool uses industry-standard open-source components like nmap and nuclei, providing high transparency for security engineers who need to verify the underlying scan logic.

How does qsa.sh compare to Shodan or Censys?

While Shodan and Censys offer massive global datasets, qsa.sh focuses on frictionless, terminal-native execution for specific IP scans, catering to a 'terminal-first' developer workflow.

What are the main technical limitations of the site?

The site currently suffers from aggressive no-store caching headers and a noindexed contact page, which impacts performance efficiency and high-intent user conversions.

Is the service free to use?

The business model is freemium with a pay-per-scan option. The tool is highly accessible, and pricing is transparent for the available tiers.

Answers are based on SiteList's latest evidence review. Read the full review.

The expert review

qsa.sh earns a 86/100, distinguishing itself through an exceptional terminal-first usability and performance profile for security engineers. However, its market growth is currently limited by a critical lack of middle-of-funnel content and technical configuration oversights.

86/100: Exceptional technical utility hindered by content gaps and configuration errors.

Read the full review

Verified user reviews

0 verified

No reviews yet. The evidence locker is empty.

Reviews from verified users appear here once approved.

Reviews are from the SiteList community. Some reviewers received incentives — disclosed in the review, always. The verdict is never for sale.

Scores across 13 dimensions

Domain
qsa.sh
Category
Security monitoring
Platforms
web
Last checked
Aug 3, 2026
Public dimensions
13

Home

Fixvibe screenshot 1 of 4: Home

Fixvibe

Score 83 out of 100 — Strong

fixvibe.app

Security scanner for AI-generated web apps, including DAST, BaaS misconfiguration checks, leaked-secret detection, and AI-ready remediation prompts.

Home

VulnWatch Agency — Branded website security reports for digital agencies screenshot 1 of 4: Home

VulnWatch Agency — Branded website security reports for digital agencies

Score 77 out of 100 — Strong

vulnwatch.tech

VulnWatch is an automated website vulnerability scanner that uses a proprietary AI Analyst module to transform raw scanner data into prioritized security reports. It provides executive summaries, ranked risks, and actionable remediation plans for web applications, WordPress sites, and network services.

Home

Duckduckgoose screenshot 1 of 4: Home

Duckduckgoose

Score 69 out of 100 — Fair

duckduckgoose.ai

DuckDuckGoose builds explainable deepfake detection for identity, fraud and compliance teams, backing every verdict with forensic evidence.